CVE-2026-4907 Details
Description
A vulnerability was identified in Page-Replica Page Replica up to e4a7f52e75093ee318b4d5a9a9db6751050d2ad0. The impacted element is the function sitemap.fetch of the file /sitemap of the component Endpoint. The manipulation of the argument url leads to server-side request forgery. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The vendor was contacted early about this disclosure but did not respond in any way.
A server-side request forgery (SSRF) vulnerability has been identified in Page Replica versions prior to e4a7f52e75093ee318b4d5a9a9db6751050d2ad0. The issue arises in the Endpoint component, specifically within the sitemap.fetch function of the /sitemap file. The vulnerability allows remote attackers to manipulate the url parameter, leading to unauthorized outbound requests from the server to attacker-specified locations. This could be exploited to access internal services, cloud metadata, or other restricted resources.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Mar 27, 2026CISA-ADP
Assessed Mar 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/lakshayyverma/CVE-Discovery/blob/main/page_replica.md | [email protected] | Technical Analysis |
| https://vuldb.com/?ctiid.353658 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/?id.353658 | [email protected] | AdvisoryExploitPartial Content |
| https://vuldb.com/?submit.777447 | [email protected] | Technical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Page Replica | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Mar 27, 2026 | New CVE Received | [email protected] |
Volerion